BitlockMove Tool Enables Lateral Movement via Bitlocker DCOM & COM Hijacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new proof-of-concept (PoC) tool named BitlockMove demonstrates a novel lateral movement technique that leverages BitLocker’s Distributed Component Object Model (DCOM) interfaces and COM hijacking. Released by security researcher Fabian Mosch of r-tec Cyber Security, the tool enables attackers to …

Weekly Cybersecurity News Recap : Tenable, Qualys, Workday Data Breaches and Security Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

This week in cybersecurity serves as a critical reminder of the pervasive risks within the digital supply chain, as several industry-leading companies disclosed significant data breaches. The incidents, affecting vulnerability management giants Tenable and Qualys, as well as enterprise software …

FBI Unveils IOCs for Hacker Groups Targeting Salesforce Instances for Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Bureau of Investigation (FBI) has released a flash alert detailing the activities of two cybercriminal groups, UNC6040 and UNC6395, that are actively compromising Salesforce environments to steal data for extortion purposes. The advisory, published by the FBI on …

Nmap vs. Wireshark: Choosing the Right Tool for Network Penetration Testing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Nmap vs Wireshark are the most popular Network penetration testing tools. Security professionals face an increasingly complex threat landscape, and picking the right penetration testing tools can make the difference between a secure infrastructure and a compromised network. While both …

EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware campaign has emerged that leverages artificial intelligence to create deceptively legitimate applications, marking a significant evolution in cyberthreat tactics. The EvilAI malware family represents a new breed of threats that combines AI-generated code with traditional trojan techniques …

New Malvertising Campaign Leverages GitHub Repository to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malvertising campaign has emerged, exploiting GitHub repositories through dangling commits to distribute malware via fake GitHub Desktop clients. This novel attack vector represents a significant evolution in cybercriminal tactics, leveraging the trust and legitimacy associated with GitHub’s platform …

Buterat Backdoor Attacking Enterprises to Establish Persistence and Control Endpoints

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated backdoor malware known as Backdoor.WIN32.Buterat has emerged as a significant threat to enterprise networks, demonstrating advanced persistence techniques and stealth capabilities that enable attackers to maintain long-term unauthorized access to compromised systems. The malware has been identified targeting …

New Malware Attack Leverages SVGs, Email Attachments to Deliver XWorm and Remcos RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated malware campaign that exploits SVG (Scalable Vector Graphics) files and email attachments to distribute dangerous Remote Access Trojans, specifically XWorm and Remcos RAT. This emerging threat represents a significant evolution in attack methodologies, as …

What Are The Takeaways From The Scattered LAPSUS $Hunters Statement?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The well-known group of cybercriminals called Scattered Lapsus$ Hunters released a surprising farewell statement on BreachForums. This manifesto, a mix of confession and strategic deception, offers vital insights into the changing landscape of modern cybercrime and the increasing pressure from …

ChatGPT’s New Support for MCP Tools Let Attackers Exfiltrate All Private Details From Email

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly introduced feature in ChatGPT that allows it to connect with personal data applications can be exploited by attackers to exfiltrate private information from a user’s email account. The attack requires only the victim’s email address and leverages a …